2629 | (POC) Untrim any live video on Facebook |
Authorization flaw |
Meta / Facebook |
Ahmad Talahmeh |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2628 | Unauthorized access to admin setpassword page BY bypassing 403 Forbidden |
Authorization flaw |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2615 | Telegram bug bounties: XSS, privacy issues, official bot exploitation and more… |
XSS
Authorization flaw
DoS |
NA |
Davide |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2571 | Workplace by Facebook | Unauthorized access to companies environment — $27,5k |
Authorization flaw
Logic flaw
IDOR |
Meta / Facebook |
Marcos Ferreira (@mvinni_) |
Bug Bounty | 2021-05-07 | 2023-06-13 |
2497 | How I could have accessed all your private videos/photos saved inside your device without even unlocking it? |
Authorization flaw
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-06-06 | 2023-06-13 |
2494 | How i was able to bypass parental pin of showmax |
Authorization flaw |
Showmax |
abdulsec (@moodiAbdoul) |
Bug Bounty | 2021-06-09 | 2023-06-13 |
2485 | [Google VRP] Privilege escalation on https://dialogflow.cloud.google.com |
Authorization flaw
Logic flaw |
Google |
lalka (@0x01alka) |
Bug Bounty | 2021-06-13 | 2023-06-13 |
2465 | Accessing Restricted Documents With Extra JSON Body Content |
Mass assignment
Authorization flaw |
NA |
Imran Huda (@imranHudaA) |
Bug Bounty | 2021-06-18 | 2023-06-13 |
2415 | Part 2: Dive into Zoom Applications |
CSRF
Account takeover
Information disclosure
Session expiration issue
Authorization flaw
Logic flaw |
Zoom |
Rakesh Thodupunoori (@rakesh_3895) |
Bug Bounty | 2021-07-13 | 2023-06-13 |
2401 | Facebook Vulnerability: $1500 for Removing Document Cover |
Authorization flaw
IDOR |
Meta / Facebook |
Muhammad Sholikhin (@MuhammadLikhin) |
Bug Bounty | 2021-07-18 | 2023-06-13 |
2328 | How we was able to takeover whole organization via Privilege Escalation |
Privilege escalation
Authorization flaw |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-08-13 | 2023-06-13 |
2288 | How did I earned 6000$ from tokens and scopes in one day |
Authorization flaw
Privilege escalation |
NA |
Corraldev (@javier_corralg) |
Bug Bounty | 2021-08-27 | 2023-06-13 |
2232 | Bypassing GCP Org Policy with Custom Metadata |
Authorization flaw |
Google |
Kat Traxler (@NightmareJS) |
Bug Bounty | 2021-09-10 | 2023-06-13 |
2183 | Force Browsing bug at Facebook business plan ($500 Bounty) |
Authorization flaw
Forced browsing |
Meta / Facebook |
Dewanand Vishal (@dewcode91) |
Bug Bounty | 2021-09-29 | 2023-06-13 |
2164 | Accessing Apple’s internal UAT Slackbot for fun and non-profit |
Authorization flaw |
Apple |
Shail Patel (@shail_official) |
Bug Bounty | 2021-10-07 | 2023-06-13 |
2049 | RocketChat - Monitor User Messages |
Authorization flaw |
Rocket.Chat |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2021-11-25 | 2023-06-13 |
1991 | Hacked Google-Meet…??! |
Authorization flaw |
Google |
7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157) |
Bug Bounty | 2021-12-18 | 2023-06-13 |
1958 | Bypassing Identity-Aware Proxy - Google Cloud Vulnerability |
Authorization flaw
Token leak
OAuth |
Google |
SebLu |
Bug Bounty | 2021-12-30 | 2023-06-13 |
1947 | How i was able to bypass a Pin code Protection |
Authorization flaw |
NA |
Kerolos sameh (@xko2xx) |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1914 | How i found “Broken Access Control Through out-of-sync setup” and got $1000 |
Broken Access Control
Authorization flaw |
NA |
Mr Robert | Ahmed M Hassan (@Mr_Robert20) |
Bug Bounty | 2022-01-16 | 2023-06-13 |
1905 | How I messed up my own profile data |
Authorization flaw |
NA |
Himmat Singh |
Bug Bounty | 2022-01-20 | 2023-06-13 |
1874 | Access Control Violation – Wiki Page Creation |
Authorization flaw |
NA |
Nick Berrie (@machevalia) |
Bug Bounty | 2022-01-30 | 2023-06-13 |
1808 | 403 forbidden bypass & Accessing config files using a header |
403 bypass
Authorization flaw |
NA |
vishnurajr |
Bug Bounty | 2022-02-17 | 2023-06-13 |
1796 | Send a Email to me and get kicked out of Google Groups !! — #GoogleVRP — A Feature that almost broke Google Groups !! |
Logic flaw
Authorization flaw |
Google |
Sriram Kesavan (@sriramoffcl) |
Bug Bounty | 2022-02-20 | 2023-06-13 |
1753 | Demographic Misconfiguration on Facebook live |
Logic flaw
Authorization flaw |
Meta / Facebook |
Prajwol Dhungana (@PrajwolDhunga14) |
Bug Bounty | 2022-03-09 | 2023-06-13 |